VulnerabilityDeferred
CVE-2024-39934
Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup is enabled, because the "shared holotree usage" feature allows any user to edit any Python environment.
HIGH 7.8EPSS 0.18%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup is enabled, because the "shared holotree usage" feature allows any user to edit any Python environment.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.18% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Source
- cve@mitre.org
References
- https://checkmk.com/werk/16434
- https://github.com/elabit/robotmk/commit/78c1174ab2df43813050d0c22e1efb8636f8715e
- https://github.com/elabit/robotmk/compare/v2.0.0...v2.0.1
- https://github.com/elabit/robotmk/releases/tag/v2.0.1
- https://checkmk.com/werk/16434
- https://github.com/elabit/robotmk/commit/78c1174ab2df43813050d0c22e1efb8636f8715e
- https://github.com/elabit/robotmk/compare/v2.0.0...v2.0.1
- https://github.com/elabit/robotmk/releases/tag/v2.0.1
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.